GIFCT Partners with UK Home Office on File Sharing Report

GIFCT Partners with UK Home Office on File Sharing Report
13 August 2026 GIFCT Team
In News

This insight was written by GIFCT Trust and Safety Solutions Associate Jessa Mellea and GIFCT Membership and Programs Associate Charley G. 

In April 2025, the Global Internet Forum to Counter Terrorism (GIFCT) partnered with the UK Home Office on a project examining terrorist and violent extremist (TVE) exploitation of online file-sharing services, as well as response and mitigation strategies. Below, we set out the key findings of the report and outline cross-sector recommendations for tech companies, governments, and civil society. The full report is available only to GIFCT Members. If you are a tech platform interested in joining GIFCT, please find all information about the application process here.

Terrorist and violent extremist (TVE) exploitation of file-sharing services is not a new phenomenon. It has remained an issue for over a decade and the focus of significant landmark research into understanding how networks like Daesh and Al-Qa’ida operate online. In recent years, other ideologically motivated individuals and groups have experimented with exploiting file-sharing services to further recruitment, propaganda, and radicalization goals. 

The project aimed to analyze why terrorists and violent extremists target file-sharing platforms; discuss current exploitation methods using specific case studies to map how they are targeted; identify current mitigation strategies for countering this exploitation; and outline recommendations for tech companies, governments, and civil society to address TVE exploitation within existing frameworks.

Summary of Key Findings

File-sharing platforms play an integral role in TVE exploitation of the internet, both in hosting content and in being used to circumvent content moderation efforts elsewhere online. Key findings highlight the current landscape of TVE exploitation of file-sharing platforms, explore why terrorists and violent extremists find these platforms desirable, examine how exploitation differs across ideological strands, and present specific use cases and current mitigation and content moderation strategies aimed at safeguarding these platforms. Terrorists and violent extremists typically exploit file-sharing platforms for a range of purposes, which allow TVE content to remain online for longer. This includes: increased personal and operational security, challenges in content moderation, ease of use, high levels of audience reach, and specific security features including self-deleting content.

Islamist extremist terrorists regularly exploit file-sharing services to distribute original and edited content, including posting the same content across a range of file-sharing services to reduce the impact of content moderation efforts and make it easier for networks to identify content still online. Their preference for file-sharing services does not appear linked to those with reduced content moderation capacity. Instead, it seems based on familiarity and specific security features, including end-to-end encryption and anonymous uploads. Extreme right wing terrorists (ERWT) (also commonly referred to as racially or ethnically motivated violent extremists, or domestic violent extremists) exploit file-sharing platforms significantly less, though activity has historically peaked in the immediate aftermath of ERWT-related attacks to share perpetrator-created content. ERWTs more regularly exploit file-sharing platforms to distribute historic Nazi material. 

Despite current moderation practices such as specific policies against sharing TVE material, hash matching, user and law enforcement reporting mechanisms, and increased barriers for users attempting to upload such content, this content remains available. This highlights the challenges of countering widespread and cross-platform exploitation. Notably, monitoring and moderation of outlinks to file-sharing platforms posted elsewhere online is exceptionally difficult, and identifying potentially violative URLs remains an ongoing challenge across the tech sector.

Recommendations

Based on the analysis, the report presents the following recommendations.

Tech Sector Recommendations

As an inherently cross-platform phenomenon, countering TVE exploitation of file sharing will benefit from coordinated efforts among platforms. File-sharing platforms (where violative content is hosted), social platforms (where links to content are shared), and URL shortening services (used to obscure content and evade moderation), among other platforms, should coordinate efforts to identify and disrupt TVE exploitation of file sharing in the following ways:

Tooling / operational recommendations
  1. Tech platforms could consider signal-sharing with other platforms, including sharing hashes, URLs, file names, and behavioral signals, which would aid in moderating content at the point of upload, or in a faster, coordinated manner after upload, increasing proactive efforts.
  2. Investigative teams in the tech sector could consider investing in tools that allow investigators to safely view content from file-sharing sites and follow shortened links without being targeted by adversarial actors, malware, or other cyberthreats. Likewise, file-sharing and URL shortening services should consider building these features into their platforms.
  3. Development teams should ensure features have easy-to-use user reporting functions, so that others can flag potentially violative content to moderators. Where possible, this will allow reporting even when a user does not have an account, reducing barriers to reporting.
Policy team recommendations
  1. Policy teams at platforms should ensure that their usage policies (for example, Terms of Use or Community Guidelines) explicitly prohibit use for TVE purposes, including sharing such content on the platform, linking to such content hosted elsewhere, and using URL shorteners and similar platforms to evade content moderation efforts.
  2. Policy teams, particularly those at large tech companies, could streamline policy language across platforms and products to ensure content moderation standards are clear and equally enforced across product types.
  3. Policy and development teams could enhance user reporting and appeals mechanisms, ensuring they are easy to use, including via the development of webpages and guidebooks on how to submit content for review as well as how to dispute moderated content. 
  4. Policy and development teams should collaborate on solutions for when TVE activity is detected on file-sharing platforms. This could include pop-ups to users that request academic or journalistic verification (e.g., institutional login) to aid in understanding intent of hosting TVE material. Where possible, settings could also use a private hosting approach, with limited options for public sharing of potentially violative content.

Recommendations for Governments / Law Enforcement / Legislators / Regulators

Governments, law enforcement agencies, legislators, and regulators each engage with the challenge of TVE exploitation of file-sharing platforms in different capacities – from developing policy and legal frameworks to sharing threat intelligence and enforcing compliance. Coordination among these stakeholder groups would maximize impact, foster consistency, and support a tailored approach to the operational realities facing file-sharing platforms. To that end:

  1. Governments could develop and share resources such as updated keyword lists, logos, and other identifiers to help file-sharing platforms detect and block TVE content effectively. 
  2. Sharing regular, ongoing analysis and threat insights from key stakeholder groups, like governments and law enforcement, with   file-sharing platforms in an agreed format would help produce actionable and useful information. This could take place, for example, via verbal or restricted-access briefings, helping platforms to improve moderation and respond effectively to emerging risk.
  3. Governments should consider investing in training led by external organizations with expertise and networks in terrorism content online like GIFCT and/or other relevant civil society organizations to better understand the operational and technical challenges faced by file-sharing platforms, ensuring tailored support.
  4. Governments should ensure consistency of language and definitions when engaging with file-sharing platforms on tackling TVE content, and maintain this consistency across law enforcement, regulators, lawmakers, and other related actors that engage with these platforms. Alignment with regional and/or international frameworks and definitions is particularly helpful for industry standardization efforts. 
  5. Ensuring a streamlined approach to regulation could help ensure that file-sharing platforms, where relevant, are recognized for their important role in the wider digital ecosystem and tackling terrorism content online.

Recommendations for Civil Society Organizations

Fostering multi-stakeholder engagement, including by providing funding, technical assistance, access, and other support, can help ensure that experts, practitioners,  and civil society organizations with relevant expertise can support more effective responses tackling terrorist and violent extremist use of file sharing.  

  1. Processes to develop and review platform policies should, as appropriate, include relevant experts and civil society organizations to help ensure they are robust, transparent, and align with human rights obligations, including freedom of expression. This could be done through multi-stakeholder consultations or working groups.
  2. Civil society should be included where relevant within dialogues in a collaborative space to work with tech companies, governments, and affected communities. This collaboration could include efforts to share good practices, lessons learned, and raise awareness about the impacts and effectiveness of measures. 
  3. Building capacity for civil society organizations can help strengthen their expertise to collaborate with tech platforms and support measures to prevent terrorists and violent extremists from exploiting digital platforms. To that end, developing dedicated resources and guidance on issues like keywords, symbols, logos, and content moderation evasion strategies, with file-sharing platforms, can help to improve their moderation efforts. This could be done through the Global Network on Extremism and Technology, for example.

Join Our Community

Working to counter TVE content and activity is a multi-stakeholder effort that requires input, action, and collaboration across sectors and organizations. This report highlights GIFCT’s efforts to work closely with partners across sectors to ensure those at the forefront of tackling terrorism and violent extremism online are well equipped with up-to-date, in-depth analysis from subject matter experts. 

GIFCT Working Groups, events, and partnerships convene experts from diverse stakeholder groups, geographies, and disciplines to engage on critical themes related to countering terrorism and violent extremism online. GIFCT encourages tech companies of all sizes to join its membership community where members have exclusive access to a suite of technical solutions, tools, and resources that empower their work towards improving online safety for all.